← Home

@dword-design/eslint-config

15
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

dword-design

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:eslint-plugin-vue AI (dependencies): eslint-plugin-vue is a well-known, widely-used official Vue.js ESLint plugin; expected dependency for a comprehensive ESLint config. ai
dependencies unvetted-dep:vue-eslint-parser AI (dependencies): vue-eslint-parser is the official Vue SFC parser for ESLint; expected in an ESLint config that supports Vue. ai
dependencies unvetted-dep:eslint-plugin-jsonc AI (dependencies): eslint-plugin-jsonc is a well-known ESLint plugin for JSON/JSONC linting; legitimate dependency for an ESLint config package. ai
dependencies unvetted-dep:depcheck-package-name AI (dependencies): depcheck-package-name is a utility for resolving package names; legitimate use in an ESLint config context. ai
dependencies unvetted-dep:eslint-plugin-playwright AI (dependencies): eslint-plugin-playwright is the official Playwright ESLint plugin; expected in a comprehensive ESLint config. ai
dependencies unvetted-dep:eslint-plugin-prefer-arrow AI (dependencies): eslint-plugin-prefer-arrow is a well-known ESLint plugin; legitimate dependency for an ESLint config package. ai
dependencies unvetted-dep:eslint-plugin-sort-keys-fix AI (dependencies): eslint-plugin-sort-keys-fix is a well-known ESLint plugin; legitimate dependency for an ESLint config package. ai
dependencies unvetted-dep:eslint-config-flat-gitignore AI (dependencies): eslint-config-flat-gitignore is a utility for ESLint flat config gitignore support; legitimate dependency. ai
dependencies unvetted-dep:@dword-design/eslint-plugin-import-alias AI (dependencies): This is the author's own ESLint plugin, consistent with the package's scope and authorship. ai
phantom-deps phantom-dep:prettier AI (phantom-deps): ESLint config packages commonly reference prettier as a plugin/config without direct import; this is normal for flat config setups. ai
phantom-deps phantom-dep:vue-eslint-parser AI (phantom-deps): Parser references in ESLint flat configs are passed as objects/strings, not directly imported in the traditional sense. ai
phantom-deps phantom-dep:eslint-config-prettier AI (phantom-deps): ESLint config packages spread other configs without necessarily importing them directly; normal pattern. ai
phantom-deps phantom-dep:eslint-plugin-prefer-arrow AI (phantom-deps): ESLint plugins in flat configs are often referenced indirectly through config composition; normal pattern. ai
phantom-deps phantom-dep:eslint-plugin-sort-keys-fix AI (phantom-deps): ESLint plugins in flat configs are often referenced indirectly through config composition; normal pattern. ai
phantom-deps phantom-dep:eslint-plugin-simple-import-sort AI (phantom-deps): ESLint plugins in flat configs are often referenced indirectly through config composition; normal pattern. ai

Versions (showing 15 of 15)

Version Deps Published
9.0.13 25 / 6
9.0.12 25 / 6
9.0.11 25 / 6
9.0.10 25 / 6
9.0.9 25 / 6
9.0.8 25 / 6
9.0.7 25 / 5
9.0.6 25 / 5
9.0.5 25 / 5
9.0.4 25 / 5
9.0.3 25 / 5
9.0.2 25 / 5
9.0.1 25 / 5
9.0.0 25 / 5
8.1.0 26 / 4

v9.0.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v9.0.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v9.0.11

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v9.0.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.